Improper access control in Backdrop CMS - #VU105896

 

Improper access control in Backdrop CMS - #VU105896

Published: March 20, 2025


Vulnerability identifier: #VU105896
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to a bug in the core Actions system. A remote attacker can use bulk actions to modify some values that they would not have permission to modify when editing individual nodes.


Affected software

Backdrop CMS

Remediation

Install updates from vendor's website.

Backdrop CMS - addressed in versions 1.29.4, 1.30.2

External References

Related Security Bulletins